Review of 2025: The Year the Firewalls Themselves Became the Target

Fortinet, Cisco, Juniper, F5: in 2025, attackers systematically targeted firewalls, VPN gateways, and management layers. A review with lessons.

Anyone who lays the 2025 security advisories side by side sees a pattern: attackers no longer primarily tried to get past firewalls and VPN gateways – they took over the devices themselves. Zero-days in FortiOS, PAN-OS, and Cisco ASA, backdoors on Juniper routers, a break-in to F5’s development environment: the perimeter that is meant to protect was, in 2025, the preferred target. This review places the most important incidents in chronological order – soberly, because there is nothing to dramatize here. For mid-sized companies that operate exactly these devices at the network edge, the consequences are concrete.

January: Fortinet zero-day and an old leak

On January 14, 2025, Fortinet published advisory FG-IR-24-535 on CVE-2024-55591 (CVSS 9.6, per NVD 9.8), an authentication bypass in FortiOS and FortiProxy that had already been actively exploited since mid-November 2024: attackers created admin accounts unnoticed and changed SSL-VPN groups. CISA added the flaw to the KEV catalog the same day, and the BSI issued a warning. Also on the same day, a group called “Belsen Group” published configurations and VPN credentials of over 15,000 FortiGates – captured in 2022 via CVE-2022-40684. This also affected long-since-patched devices whose old credentials had never been rotated.

January: “J-magic” – the listening backdoor

On January 23, Lumen Black Lotus Labs described a campaign against Juniper routers in enterprise networks: a passive backdoor that waited for a crafted “magic packet” and only then opened a connection. According to the researchers’ assessment, the campaign ran roughly from September 2023 to mid-2024; about half of the affected devices served as VPN gateways. There is no CVE, and the original infection path remained unexplained – a lesson in how little visibility there usually is on network devices.

February: PAN-OS management interface

With CVE-2025-0108, an authentication bypass in the management web interface of Palo Alto PAN-OS became public on February 12. As early as February 18, active exploitation was confirmed – chained with CVE-2025-0111 and the older CVE-2024-9474; CISA added the flaws to the KEV catalog. Vulnerable was essentially anyone who made the management interface reachable from the internet. That was – and is – alarmingly often the case.

March: UNC3886 on Juniper routers

On March 12, Mandiant documented a campaign attributed by researchers to a China-nexus actor named UNC3886: via CVE-2025-21590, the Veriexec integrity protection of Junos OS was bypassed and TINYSHELL-based backdoors installed – predominantly on MX routers that had reached their end of life. Juniper responded with JSA93446 and a reference advisory, and CISA listed the flaw in the KEV catalog on March 13. Legacy devices at the network edge were here not only unpatched but effectively no longer defensible.

April: Persistence that survives patching

In April, Fortinet reported a late consequence of older SSL-VPN flaws (among them CVE-2022-42475, CVE-2023-27997, CVE-2024-21762): on compromised devices, attackers had placed a symlink in the SSL-VPN language-file folder that allowed read access to the device configuration – and survived later patches. Estimates ranged between 14,000 and 16,600 affected devices. Only builds 7.6.2, 7.4.7, 7.2.11, 7.0.17, and 6.4.16 detect and remove the symlink. The lesson: a patch closes the flaw but does not automatically end an already existing compromise.

May: FortiVoice zero-day

CVE-2025-32756 (CVSS 9.6, advisory FG-IR-25-254 of May 13): a stack overflow with remote code execution, exploited as a zero-day against FortiVoice – including the targeted deletion of log traces. Five Fortinet product lines were affected; CISA added the flaw to the KEV catalog on May 14. The pattern – zero-day, unnoticed access, trace removal – matched exactly that of the firewall cases, only this time via the phone system.

June and July: Cisco ISE with CVSS 10.0 three times

On June 25, Cisco published patches for two unauthenticated RCE flaws in the Identity Services Engine (CVE-2025-20281, -20282); in mid-July a third followed with CVE-2025-20337 – all rated with the maximum score of CVSS 10.0. Toward the end of July, active exploitation was confirmed; CISA followed on July 28 with the KEV entry for two of the three flaws. There was no workaround, only the patch helped. Of all things, the central instance for network access control thus itself became the entry point.

September: Cisco’s double emergency

The end of the month brought two zero-day reports within two days. First: CVE-2025-20333 (CVSS 9.9) and CVE-2025-20362, chained for a full takeover of ASA and FTD firewalls, exploited since about May 2025 – with the malware RayInitiator/LINE VIPER, which survived reboots and even firmware upgrades. CISA issued Emergency Directive ED 25-03, and the BSI warned. Second: CVE-2025-20352 (CVSS 7.7), an SNMP zero-day in IOS/IOS XE, used in “Operation Zero Disco” for rootkits on older Catalyst switches (KEV inclusion on September 29).

October: The F5 break-in

On October 15, F5 disclosed via an SEC filing that a state-backed actor had had long-term access to the BIG-IP development environment – detected as early as August 9, with publication delayed at the request of the US Department of Justice. Stolen were parts of the BIG-IP source code, information on still-unpublished vulnerabilities, and configuration data of individual customers. On the same day, the quarterly notification K000156572 appeared with about 44 CVEs; CISA set a patch deadline of October 22 with Emergency Directive ED 26-01, and NCSC and BSI (2025-287083-1032) warned. Shadowserver counted about 267,000 internet-reachable BIG-IP management interfaces. The attribution to China-nexus actors named in press and research has not been confirmed by F5 itself.

November: FortiWeb, twice

In early November it became known that Fortinet had quietly patched an actively exploited path-traversal flaw in the WAF product line FortiWeb (CVE-2025-64446), which allowed an authentication bypass, with version 8.0.2 – exploited since early October, with rogue admin accounts on internet-exposed devices; the CVSS rating varies by source between 9.1 and 9.8. CISA listed the flaw in the KEV catalog on November 14. Just four days later followed the second actively exploited FortiWeb zero-day with CVE-2025-58034 (KEV inclusion on November 18).

December: FortiCloud SSO bypass

To close out the year: CVE-2025-59718 and CVE-2025-59719 (CVSS 9.1 per Fortinet, 9.8 per NVD), a login bypass in the FortiCloud SSO mechanism, disclosed on December 9 and actively exploited a few days later. One detail was explosive: SSO is automatically enabled during FortiCare registration unless the checkbox is unchecked – many operators had no idea this access path existed on their devices. Several CERTs and security service providers warned within a few days.

What mid-sized companies should learn from this

Management interfaces never belong on the internet. PAN-OS in February, FortiWeb in November, 267,000 exposed BIG-IP interfaces in October – a substantial share of the incidents worked only because administration access was publicly reachable. Administration belongs in a separate management network or behind a VPN, with restricted source addresses.

Patching alone is not enough. The Belsen leak hit patched devices via old credentials, and the Fortinet symlink and RayInitiator survived updates. Anyone who, after a relevant advisory, merely patches but checks neither admin accounts nor configuration changes and does not rotate credentials closes the door behind an attacker who is already in the room. What is needed is ongoing monitoring for rogue admins and unexpected configuration changes.

EOL hardware is a liability risk. The UNC3886 campaign ran predominantly on end-of-life routers, “Operation Zero Disco” on older switches. Devices without vendor support can no longer be defended – their continued operation at the network edge is a deliberate risk decision and should be documented as such.

Assume breach for exposed VPN appliances. Anyone who has operated an SSL-VPN gateway on the internet for years should take 2025 as an occasion to check not only the patch level but a possible prior compromise: accounts, configuration, certificates, credentials. What a dependable security concept for this looks like we describe under Cyber Security.

How sector7 supports you

As an owner-led system house, we operate and harden exactly the platforms named here – with certifications for Juniper, Cisco, HPE, F5, Fortinet, and Palo Alto Networks. Our NOC monitors customer systems around the clock and thereby also detects what patches do not cover: unexpected admin accounts, configuration changes, conspicuous device behavior. This is complemented by lived Veeam backup practice and compliance consulting on ISO 27001, NIS-2, DORA, and TISAX – at flat monthly rates within our Managed Services.

Sources

Let's talk about your situation.